[Logistics Operators (Land Freight Transport and Port Transportation)] How Incident Response Will Change with the Enforcement of the Cyber Response Capability Enhancement Act

    July 22, 2026

    Author of this article

    President and CEO

    Takaaki Kanetsuki

    The public-private partnership provisions of the so-called “Cyber Response Capability Enhancement Act” (official title: Act on the Prevention of Damage Caused by Unauthorized Acts Against Important Computers), which was enacted in May 2025, will take effect in October 2026.The covered critical infrastructure sectors include truck transportation (land freight transport) and port transportation; designated operators will be legally required to register their system assets and report cyber incidents to the government.

    For the logistics industry, this series of regulatory tightening measures is not someone else’s problem.

    In fact, we are “directly affected parties.” The ransomware attack that occurred at a container terminal in the Port of Nagoya in July 2023 (Reiwa 5) served as the direct catalyst for designating the port sector as critical infrastructure and adding port transportation to the Core Infrastructure System. At the heart of the system’s design philosophy lies an actual incident that occurred in the logistics sector.

    In this article, we will examine the practical incident response measures required of land freight and port transport operators, using a case from the Port of Nagoya as a starting point, and organize the discussion into three categories: laws, business regulations, and guidelines.

    The Starting Point for Everything: What Happened During the System Failure at the Port of Nagoya

    In July of Reiwa 5, the Nagoya Port Unified Terminal System (NUTS) was shut down due to a ransomware attack, bringing container loading and unloading operations to a halt for more than two full days. The shutdown of this port—which boasts one of the largest container handling volumes in the country—has had widespread repercussions extending beyond the port itself, resulting in trailer backlogs and logistics delays.

    At that time, even while the system was down, some cargo handling operations with vessels continued manually on-site. During the recovery phase, the procedure involved verifying the consistency between the data and the actual inventory information, and then resuming operations sequentially, starting with the terminals that were ready.

    While it is not impossible to “manage manually even if the system goes down,” this approach falls far short of normal processing capacity, and the fact that a time-consuming task—verifying data consistency—awaits during recovery serves as the starting point for considering incident response in logistics.

    The report (January Reiwa 6) by the review committee established in response to this incident outlined three institutional measures: measures under the Basic Act on Cybersecurity (adding ports to the list of critical infrastructure sectors and formulating guidelines); measures under the Port and Port Transportation Business Act (adding security items to business plan reviews); and measures under the Act on the Promotion of Economic Security (adding port transportation to the critical infrastructure framework).

    All subsequent systems are an extension of this summary.

    Legal Requirements: Notifications and Incident Reporting

    The entities directly subject to the Strengthening Act are specific social infrastructure operators (core infrastructure operators) designated under the Economic Security Promotion Act; as of April 1, Reiwa 8, a total of 257 such operators have been designated across all sectors.

    The designation of logistics-related entities is a relatively recent development. In the port transportation sector, following a legislative amendment (enacted in May Reiwa 6), the system came into effect in April Reiwa 7, and operators were designated on May 1 of that year. After a transitional period, prior notification and review procedures regarding the outsourcing of Terminal Operation System (TOS) implementation and maintenance began on November 2, Reiwa 7.

    In the land freight transport sector as well, operators were designated on July 14, Reiwa 7, following amendments to the ministerial ordinance defining the scope of applicable facilities.

    The Strengthening Act imposes the following obligations on designated operators: They must report to the government the vendor names and product information for “specified critical computers” among the information systems involved in core business operations; and they must report incidents in the event of a cyberattack.

    Regarding the reporting framework, the draft guidelines for implementation presented to the Cabinet Office’s Expert Panel outline a two-stage reporting process.Upon becoming aware of an incident, an organization must promptly issue a “preliminary report” and submit a “detailed report” within 30 days. In both cases, organizations are only required to report the information known at that time; they are not expected to provide a complete root cause analysis during the initial response phase. The scope of reporting includes not only traces of “specified unlawful acts,” such as unauthorized access, but also related events. The system is designed so that the reporting obligation begins as early as the warning signs stage.

    The procedures for handling such incidents in cloud environments have also been clarified. In the case of SaaS or PaaS (related to middleware or operating systems), an incident is deemed to have been “acknowledged” at the time the cloud service provider issues a notification. Businesses that use cloud services for systems such as dispatch management, operations management, warehouse management (WMS), and transportation management (TMS) must establish in advance a designated point of contact for receiving notifications of outages or security breaches from vendors, as well as procedures for incorporating such notifications into their reporting workflow.

    The penalties cannot be overlooked either. Violating the reporting obligation and failing to comply with a corrective order issued by the regulatory authority is punishable by a fine of up to 2 million yen, while failing to comply with a request to submit documents or other materials is punishable by a fine of up to 300,000 yen.

    Furthermore, one aspect that the logistics industry should be particularly mindful of is the ripple effect on non-designated operators. It has been pointed out that IT vendors and group companies entrusted with the operation of specified critical computers—as well as equipment owned by subcontractors, depending on the system configuration—may also be subject to these regulations.

    In the logistics sector, where a multi-tiered structure of prime contractors and subcontractors is the norm and system and data integration among businesses is advancing, it is entirely possible that a company could be drawn into the system as a “subcontractor or connected party of a designated operator”—even if it has not been designated itself.

    The review process has “already” begun for port transportation.

    Even before the Enforcement Act takes effect, a mechanism with binding force is already in place in the port transportation sector. Under the amended Enforcement Regulations of the Port Transportation Business Act (effective March 31, Reiwa 6), business plans submitted for review when entering the general port transportation business—among other scenarios—are now required to include an overview of the TOS and details regarding information security measures. This mechanism allows the national government to verify the status of TOS security measures through the review of business plans.

    Unlike the guidelines, which are merely recommendations, this is a mandatory requirement for business plan applications. In the world of port transportation, it can be said that security measures have already taken a step forward, evolving from “something that is desirable to do” to “a prerequisite for conducting business.”

    "Practical Incident Response" as Outlined in the Guidelines

    The Ministry of Land, Infrastructure, Transport and Tourism has established three safety guidelines for the logistics sector—covering “Freight Truck Transportation,” “Warehousing,” and “Vessel Operations” (all first editions enacted in April Reiwa 6)—as well as the “Safety Guidelines for Ensuring Information Security in the Port Sector” for the port sector. The port sector guidelines have undergone repeated revisions since their first edition in April Reiwa 6, and the third edition was published in May Reiwa 8.The fact that the first edition was released just nine months after the incident at the Port of Nagoya, and that it has been revised annually since then, demonstrates the government’s sense of urgency regarding this sector.

    Although these guidelines are merely recommended standards that do not involve government audits, they provide a practical foundation for fulfilling reporting obligations under the Enhanced Act. Here are some key points to keep in mind from an incident response perspective.

    • Establishing a System That Involves Senior Management

      Based on the recognition that it is difficult to prevent all cyberattacks—which are becoming increasingly complex and sophisticated—the guidelines for the port sector call for a response involving the entire organization, including senior management, and for strengthening incident response systems through a combination of proactive risk management and crisis management. The starting point is the understanding that this is not an issue that can be handled solely by on-site system administrators.

    • Notification and Documentation When an Incident Occurs

      The guidelines for the port sector outline specific action steps, including contacting the Ministry of Land, Infrastructure, Transport and Tourism and the police in the event of an attack, and documenting the situation chronologically as it unfolds. These chronological records serve as foundational data directly relevant to both subsequent investigations into the cause and the preliminary and detailed reports required under the Enhanced Security Act. It is essential to establish a system during peacetime that ensures recording begins the moment an anomaly is detected.

    • Preparing for Ransomware

      The guidelines clearly state that when a ransom is demanded in a ransomware attack, it is strongly recommended to refrain from paying in order to prevent further attacks. They also require that backups be taken properly and stored in a location separate from the active system. The reason the Nagoya Port incident was ultimately resolved was that the data was recovered; therefore, how backups are handled determines the very success or failure of incident response.

    • Pre-Planning of Recovery Procedures

      As the situation at the Port of Nagoya demonstrates, recovery is not simply a matter of “restarting the system and calling it a day.” The recovery phase involves tasks unique to that stage, such as verifying the consistency between data processed manually during the outage and the data in the system, as well as making decisions on the phased resumption of operations at each terminal and facility. If your company switches to manual operations during a system outage, it is highly valuable to identify in advance exactly which data sets need to be reconciled.

    What to Do Before the Law Takes Effect

    With the law set to take effect in October 2026, the actions that designated (or potential designated) businesses need to take are becoming clearer.

    1. Asset Inventory

      We will identify specific critical computers and peripheral devices that may be subject to reporting requirements. In the case of port transportation, the focus will be on the TOS; for land freight transportation, it will be dispatch and operations management systems; and for warehousing, it will be systems such as the WMS. We will identify which systems would directly lead to business disruption by working backward from the magnitude of the impact.

    2. Establishing a Reporting Process

      Incorporate the definition of “recognition” (including notifications from cloud vendors), the procedures for drafting and approving preliminary reports, and the investigation framework for submitting detailed reports within 30 days into the emergency response plan. Designing the notifications to the Ministry of Land, Infrastructure, Transport and Tourism and the police—as required by the guidelines—along with chronological records and the statutory reports under the Enhanced Act separately will cause confusion on the ground. Let’s consolidate these into a single system so that “once a record is created, it can be reused for reports to all relevant parties.”

    3. Organization, Including Business Partners

      Confirm in advance who is responsible for contacting whom and when an incident occurs, including contractors for your company’s systems, shippers, and partners involved in data exchange—such as prime contractors and subcontractors. As the incident at the Port of Nagoya demonstrated, logistics incidents do not result in damage limited to a single company. Being prepared for both scenarios—where your company is the source of the incident and where you are affected by a failure at a connected party—is a critical precaution unique to this industry.

    Some details of the law will be finalized through cabinet orders, ministerial ordinances, and operational guidelines prior to its enforcement; therefore, items referred to as “drafts” in this article are subject to change. Please refer to the official documents published by the Cabinet Office (Cyber Security and Economic Security Divisions) and the Ministry of Land, Infrastructure, Transport and Tourism for the latest information.

    And so, Incident Lake

    As we have seen so far, the real burden of complying with the Enhanced Security Act lies not so much in establishing rules during normal times as in “the practical response beginning the very moment an incident occurs.”When you consider the need to organize the facts as they are identified and issue a preliminary report promptly, maintain a chronological record while responding to the incident, compile a detailed report within 30 days, and manage reports to multiple contacts—such as the Ministry of Land, Infrastructure, Transport and Tourism, the police, and business partners—it becomes clear, as demonstrated by the Port of Nagoya incident, that logistics incidents have a wide-ranging impact, leaving the on-site response team with almost no capacity left for reporting duties.

    Incident Lake is an incident management platform that supports this entire process. It automates everything from reporting an incident to recovery, as well as the creation and management of reports, allowing staff to focus their time on what truly matters: “resolving the immediate issue and keeping logistics running.” Now that time-sensitive reporting requirements—such as preliminary and detailed reports—are becoming standard practice, we recommend transitioning your reporting and record-keeping systems to a model that doesn’t rely on individual effort.


    Reference Materials

    Author of this article

    President and CEO

    Takaaki Kanetsuki

    SIGQ Inc. Representative Director

    Graduated from the University of Tsukuba Graduate School; specializes in databases and distributed systems.
    An engineer who handles unstructured, real-time operational data—essential in the AI era.
    Joined Money Forward, Inc. as a new graduate. Engaged in management and development at various development sites, including overseas locations, such as a secondment to the Vietnam office.
    Joined Played Inc. in 2022 and is responsible for Platform Engineering. Involved in the development of large-scale distributed data systems.
    Founded SIGQ Inc. in 2024.

    Share this article

    Facebook Share ButtonX Share Button
    Backspace key

    List of Helpful Articles